Stored Cross-Site Scripting Vulnerability in LimeSurvey by LimeSurvey GmbH
CVE-2022-48010
5.4MEDIUM
What is CVE-2022-48010?
LimeSurvey v5.4.15 is vulnerable to a stored cross-site scripting (XSS) attack via the /index.php/surveyAdministration/rendersidemenulink?subaction=surveytexts component. Attackers can exploit this vulnerability by injecting malicious scripts through the Description or Welcome-message fields, enabling them to execute arbitrary web scripts or HTML. Although the vendor claims that exploiting this vulnerability requires Superadministrator privileges, which are inherently capable of customizing surveys using JavaScript, it remains a notable security concern that could lead to data exposure or manipulation.